Oddbean new post about | logout
 Don't sleep on CVE-2023-40044.

#WS_FTP #CVE_2023_40044

https://media.infosec.town/media/766de1d2-20b0-4970-8a08-6c6d7b7c0c59.png 
 @663e5b60 I am equally concerned about CVE-2023-42657. CVE-2023-40044 only affects those with the ad-hoc file transfer service, but the directory traversal potentially affects everyone. 

That said, I have ready others say the exploit for CVE-2023-40044 is fairly trivial (not sure if that's true), but I have read nothing about reproducing CVE-2023-42657.